Virtualization Newsletter
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Turn Geeks into Leaders

June 17, 11:30 AM - 12:30 PM U.S./ET (GMT-4)

Larry Bonfante, CIO of the U.S. Tennis Association, will discuss the skills and approaches that your rising IT leaders must learn to be effective in an executive capacity.

How to Handle Your New CEO: Managing Turnover at the Top

June 18, 11:00 AM - 12:00 PM U.S./Eastern (GMT-4)

Turbulent times have increased turnover at the top. Find out what Council CIOs have done to "break in" new CEOs—build relationships, set expectations, educate on the role of IT.

Mid-Market CIO Panel: Tips and Techniques for Improving Vendor Relationships

July 15, 4:00 PM - 5:00 PM U.S./Eastern (GMT-4)

We'll highlight relationship priorities and best practices identified in a Council study, and we'll interact with a CIO panel on the approaches they've used to improve strategic vendor partnerships.

Executive Competencies Assessment Tool

Assess Your Business Leadership Skills with the Council's new benchmarking tool. Rate yourself in change leadership, strategy, customer focus and more.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Microsoft: Vista Threatened by ActiveX Bugs

Vista may be safer from attack code than Windows XP, but third-party browser add-ons are still a problem.

 

November 04, 2008Computerworld

Although computers running Windows Vista are significantly less likely to be infected with attack code than machines running Windows XP, the newer operating system continues to be threatened by Microsoft Corp.'s own ActiveX browser plug-in technology, according to a report issued Monday by the company.

In the most recent installment of its twice-yearly security intelligence report, Microsoft said that PCs running Windows XP Service Pack 2 (SP2) were more than three times as likely to be infected with malware as computers running Windows Vista SP1. Machines powered by the newest XP security update, SP3, meanwhile, were more than twice as likely to be infected.

According to Microsoft, in the six months from January to June, its Malicious Software Removal Tool (MSRT) cleaned malware from just three Vista SP1 machines per thousand times the tool was run. Meanwhile, during the same period, MSRT found and wiped malicious code from 10 Windows XP SP2 systems and eight XP SP3 PCs per thousand executions. Microsoft updates and automatically redistributes the software tool to Windows users each month on Patch Tuesday.

"Our security development processes do pay off," said George Stathakopoulos, the general manager of Microsoft's product security and security engineering group, referring to work the company has put into writing more secure code for its newer software, including Vista. "We're fairly happy where Microsoft is," Stathakopoulos continued, "but ecosystemwide, we still have a problem."

That's evident from Microsoft's data for the past six months. During that time, while half of the top 10 browser-based attacks against Windows XP machines relied on vulnerabilities in Microsoft's own software, none of the top 10 attacks against Vista systems did. Instead, the overwhelming majority of the browser attacks targeting Vista leveraged bugs in third-party companies' ActiveX controls.

Vulnerabilities in ActiveX, the Microsoft technology used to create add-ins for Internet Explorer (IE), accounted for eight of the top 10 browser-based attacks against Vista in the first half of 2008. A ninth vulnerability could be exploited via ActiveX, among other means.

Two of the eight vulnerability ActiveX controls were part of RealNetworks Inc.'s RealPlayer media player plug-in; another was part of Apple Inc.'s QuickTime player. Both vendors have had to repeatedly patch their programs this year. Apple alone has patched a total of 30 QuickTime vulnerabilities in five updates in 2008.

Microsoft's numbers echo data collected by Symantec Corp. for the latter half of 2007, when ActiveX bugs accounted for 79% of all those discovered in browser plug-ins during that period.

 
 
Loading...
TOOLS
CONNECTIONS
Microsoft
Apple
Symantec
 
WHITE PAPERS

VMware vSphere (TM) and Intel (R) Xeon (R) Processor 5500 Series

The VMware vSphere (TM) and Intel Xeon processor 5500 series provides the ROI needed to succeed in an on-demand business environment.
 

Faster, Easier, more Effective IT Infrastructure

Business continuity with low administration and maintenance costs. Can you make it happen? This Oracle business brief explains how mid-sized can improve performance by creating an IT infrastructure that makes working faster, easier and more effective.
 

ERP at the Speed of Light

Without the right strategy and tools, implementation acceleration carries the risk of abbreviated end user training and change management, over-engineering of business processes, and other problems that can lead to higher over-all cost of ownership and the erosion of business benefit.
 

a Reliable and Powerful, and Affordable IT Infrastructure

This whitepaper provides an overview of the challenges midsize organizations face, and how Oracle products can help them overcome those hurdles.
 

Maximum Efficiency Gains with Virtualization

Learn best practices to optimize your infrastructure and operations department and gain the most from virtualization.
 

Manage Virtualization Initiatives

Learn how you can better manage virtualization initiatives to recognize this technologys maximum value.
 

WEBCASTS

Webcast with Dan Vesset: Investing in Business Analytics Technology

What exactly is business analytics and why should you care? Dan Vesset of IDC and Gaurav Verma of SAS answer this a...
 

Capitalize on Your SAP Content

After 18 years of partnership and over 3,000 successful customer deployments, Open Text has become SAP's premier pa...
 

Enterprise Cloud Computing: Ready for Primetime?

The progression toward enterprise cloud computing is happening today, as industry leaders deploy technologies that ...
 

Preparing Your Business Services for the Future

Would you trust your network monitoring tools enough to know when something is truly halting a business service? Wh...
 

Enterprise System Management Challenges in Big Organizations with Eli Almog

In this Podcast with Eli Almog, Corporate Architect in BMC's CTO Office, discusses how IT managers can know when it...
 

BSM in the Field, Practical Insights from Peter Armaly

Have you thought about BSM, but haven't quite gotten the buy-in you need? Get down and dirty with BSM installations...
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Maximizing the Business Value of the PC Infrastructure

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Seven Ways ITIL Can Help You in an Economic Downturn

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo